Skip to content

Releases: Mo3he/Axis_Cam_OpenVPN

OpenVPN VPN 3.11.7

Choose a tag to compare

@github-actions github-actions released this 21 Aug 11:53

OpenVPN VPN 3.11.7

Packages OpenVPN3 Core 3.11.7.

Upstream changes

https://github.com/OpenVPN/openvpn3/tree/release/3.11.7

Changes

  • Update to upstream 3.11.7.

Packages

Install the signed_*.eap matching your device architecture.

Full changelog: v0.1.4...v3.11.7

OpenVPN VPN 0.1.4

Choose a tag to compare

@Mo3he Mo3he released this 19 Aug 10:14

Upgrade from 0.1.2 or 0.1.3 right away. On those versions the tunnel connects and reports connected, but carries no traffic at all.

Fix: the userspace data plane never started

0.1.2 renamed the app from OpenVPN to OpenVPN_VPN, but the tun probe still launched the netstack sidecar from the old /usr/local/packages/OpenVPN/lib path. The execl failed on every connect, so the data plane never came up:

  • the transparent port forwarders never listened
  • the inbound SOCKS5 proxy on the VPN address never listened
  • the outbound HTTP and SOCKS5 proxies never listened
  • the client logged TUN write exception: Connection refused and reconnected in a loop

0.1.0 and 0.1.1 were not affected.

The failure was invisible because the execl error path exited silently and the probe and sidecar logged under an OpenVPN syslog tag that the app log never shows. Both are fixed, so a future failure will be logged where you can see it.

Configurable forwarded ports

Also included, from 0.1.3: the directly forwarded ports are configurable instead of fixed at 80, 443 and 554. Add port 22 to reach SSH over the VPN.

80,443,554,22

Set it under Forwarded ports in Settings, or via the parameter API:

curl --digest -u <username>:<password> \
  --data "action=update&root.OpenVPN_VPN.ForwardPorts=80,443,554,22" \
  "http://<device-ip>/axis-cgi/param.cgi"

Up to 16 ports. Duplicates, out-of-range values and stray whitespace are ignored, and an empty value restores the default.

Security: every listed port is reachable from the VPN. Control access with your server's client configuration and firewall rules, and keep the camera behind its normal authentication.

Verified

Tested on an AXIS D6310 (AXIS OS 13) against a real OpenVPN server: SSH and HTTPS both work over the tunnel on the configured ports, an unconfigured port stays closed, and the client no longer restart-loops.

Packages

Package For
signed_OpenVPN_VPN_0_1_4_aarch64.eap Most cameras. AXIS OS 10.x - 13, 64-bit
signed_OpenVPN_VPN_0_1_4_armv7hf.eap AXIS OS 10.x - 13, 32-bit

Both are signed with the Axis ACAP signing service and install normally on AXIS OS 12.10 and later. Upgrading in place keeps your existing settings.

OpenVPN VPN 0.1.3

Choose a tag to compare

@Mo3he Mo3he released this 19 Aug 09:45

Do not use this release. The userspace data plane never starts, so the tunnel reports connected while carrying no traffic: no port forwarding, no SOCKS5, no outbound proxies. Fixed in v0.1.4.


Configurable forwarded ports

The directly forwarded ports are now configurable instead of fixed at 80, 443, and 554. Add port 22 to reach SSH over the VPN, or any other camera service you need for remote diagnostics.

Set them in the app's settings page under Forwarded ports, as a comma-separated list:

80,443,554,22

Or through the parameter API:

curl --digest -u <username>:<password> \
  --data "action=update&root.OpenVPN_VPN.ForwardPorts=80,443,554,22" \
  "http://<device-ip>/axis-cgi/param.cgi"

Up to 16 ports are accepted. Duplicates, out-of-range values and stray whitespace are ignored, and leaving the field empty restores the 80, 443, 554 default.

Security: every listed port is reachable from the VPN. Control access with your server's client configuration and firewall rules, and keep the camera behind its normal authentication.

Packages

Package For
signed_OpenVPN_VPN_0_1_3_aarch64.eap Most cameras. AXIS OS 10.x - 13, 64-bit
signed_OpenVPN_VPN_0_1_3_armv7hf.eap AXIS OS 10.x - 13, 32-bit

Both packages are signed with the Axis ACAP signing service and install normally on AXIS OS 12.10 and later.

Upgrading in place keeps your existing settings. A full uninstall and reinstall resets them to defaults.

OpenVPN VPN 0.1.2

Choose a tag to compare

@Mo3he Mo3he released this 24 Jul 07:06

Do not use this release. The userspace data plane never starts, so the tunnel reports connected while carrying no traffic: no port forwarding, no SOCKS5, no outbound proxies. Fixed in v0.1.4.


Fix broken app name and save settings without param.cgi

Two fixes in this release:

  • The app package name used by the bridge and web UI did not match the manifest
    appName (OpenVPN_VPN). As a result the client binary was launched from the
    wrong path, so the tunnel never started, and settings were read from the wrong
    parameter namespace. All internal references now use OpenVPN_VPN.
  • Settings (username, password, proxy ports) can now be saved on Axis devices
    that do not expose /axis-cgi/param.cgi, such as recorder/NVR products
    (e.g. S3008) and access-control controllers (e.g. A1610, A1710, A1810). The
    app serves /local/OpenVPN_VPN/api/settings; the web UI uses param.cgi when
    available and falls back to this endpoint otherwise, writing through the ACAP
    parameter store.

Packages are signed with the Axis ACAP signing service and install on
AXIS OS 12.10 and later.

OpenVPN VPN 0.1.1 (Signed)

Choose a tag to compare

@Mo3he Mo3he released this 21 Jul 17:37

These .eap packages are signed with the Axis ACAP signing service and install
normally on AXIS OS 12.10 and later.

Upgrading from an earlier version

Because the signing vendor changed, installing over a previously installed
unsigned version can fail with "Couldn't install: app". The device log
shows:

Vendor ID in manifest does not match the vendor ID of the previous version

To upgrade: back up your app configuration, uninstall the existing app,
then install this signed version.

OpenVPN Client v0.1.1

Choose a tag to compare

@Mo3he Mo3he released this 07 Jul 10:38

AXIS OS 13 readiness release.

Rebuilt on the ACAP Native SDK 12.10.0 (Ubuntu 24.04) with the changes needed to survive the AXIS OS 13 upgrade, while keeping the AXIS OS 11 floor working.

Changes:

  • 64-bit time (Y2038): recompiled against SDK 12.10.0.
  • Manifest schema v2 (2.0.0): declares compatibleOsVersions (max 13) and a vendorId.
  • Non-executable stack on all shipped binaries (GNU_STACK RW).
  • Bundles a statically linked OpenSSL 3.5 in tun_probe so it no longer depends on the device's OpenSSL version, and forwards the C23 _isoc23* symbols locally, keeping the max glibc requirement at 2.34.

Tested: live-validated on AXIS OS 11.11.212 (P3265-LVE) and 12.10.73 (Q3538-LVE) — full VPN connect on 12.10.

Install the .eap matching your camera's architecture (aarch64 or armv7hf).

OpenVPN Client v0.1.0

Choose a tag to compare

@Mo3he Mo3he released this 06 Jul 09:28

First release of the OpenVPN Client ACAP for Axis cameras.

Runs an OpenVPN client directly on the camera, entirely in userspace, with no
root and no kernel TUN device. Verified on Axis OS 12.

Features:

  • Non-root: runs as the unprivileged sdk ACAP user
  • OpenVPN3 core terminates the tunnel in userspace (socketpair instead of /dev/net/tun)
  • gVisor netstack + proxy layer: transparent forwarders for 80/443/554,
    inbound SOCKS5, outbound HTTP CONNECT and SOCKS5
  • Reach the camera from your VPN, and route camera traffic out through it
  • Web UI to upload the .ovpn profile, set credentials and proxy ports, and view logs

Install the .eap matching your camera architecture (aarch64 or armv7hf) via
Apps then Add app.

Licensed under AGPL-3.0. See THIRD_PARTY_NOTICES.md for bundled components.